Access control
Access is granted per menu item. A role is built by ticking the screens it may reach, so it can be exactly as broad as the job actually is — and no broader.
- Roles are built from the menu tree itself: every screen in the application is a tick box.
- Assign a role to a user; change the role and everyone on it moves at once.
- Hide whole modules — payroll, the general ledger, system settings — from people with no business in them.
- Separate duties properly: the person who keys vouchers need not be the person who approves and posts them.
- Each user still has their own login, language, number and date formats.
- Users can be locked out without being deleted, so their history stays intact.
- Administrators can see and change any role from System > Roles.
Creating a role
- Open System › Roles › Add Role and name it.
- The access control block is the whole menu tree, every screen a tick box. Everything starts ticked; untick a module to hide it entirely, or open it and untick individual screens.
- Save. The role list shows, per role, exactly what is disabled.
Giving someone a login
- Open the employee under HR › Employees (or add one). Enter a Login and Password and pick the Role.
- Tick Sales if they should appear in the salesperson drop-down; tick E-mail TAN to require a code sent by email on each login.
- Save. They sign in with that login; their own preferences (language, formats) are under System › Preferences once they are in. To suspend someone, clear the login; their history stays.
Every dataset on our hosting has this, from day one.
Create your free account or ask us about migrating